cbcvebase.
CVE-2021-34593
published 2021-10-26

CVE-2021-34593: In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

Affected

17 ranges
VendorProductVersion rangeFixed in
codesyscodesys_v2>= PLCWinNT < V2.4.7.56V2.4.7.56
codesyscodesys_v2>= Runtime Toolkit 32 bit full < V2.4.7.56V2.4.7.56
codesysplcwinnt< 2.4.7.562.4.7.56
codesysruntime_toolkit< 2.4.7.562.4.7.56
wago750-8202_firmware< fw20fw20
wago750-8203_firmware< fw20fw20
wago750-8204_firmware< fw20fw20
wago750-8206_firmware< fw20fw20
wago750-8207_firmware< fw20fw20
wago750-8208_firmware< fw20fw20
wago750-8210_firmware< fw20fw20
wago750-8211_firmware< fw20fw20
wago750-8212_firmware< fw20fw20
wago750-8213_firmware< fw20fw20
wago750-8214_firmware< fw20fw20
wago750-8216_firmware< fw20fw20
wago750-8217_firmware< fw20fw20